Data processing method and device based on Ethernet ring network, and electronic equipment
By using an Ethernet ring network architecture and dual transmission path design, combined with CRC, FCS, and TSN technologies, the problem of traditional vehicle bus technology failing to meet the high bandwidth and real-time requirements of L3+ autonomous driving is solved, enhancing the reliability and security of data transmission and enabling functional safety fault monitoring for L3+ autonomous driving.
Patent Information
- Application Number
- CN202511175589.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-21
- Publication Date
- 2025-11-14
AI Technical Summary
Traditional vehicle bus technology cannot meet the high bandwidth and real-time requirements of L3+ autonomous driving, and traditional Ethernet applications lack functional safety fault monitoring mechanisms, resulting in unreliable and insecure data transmission.
An Ethernet ring network architecture is adopted, and data is protected through a dual transmission path design. Cross-checking is performed at the first area controller, and CRC, FCS and TSN technologies are combined to ensure data integrity and real-time performance. Redundancy switching strategy is used to ensure the reliability and security of data transmission.
It achieves high-bandwidth data transmission, meeting the real-time requirements of L3+ autonomous driving, and enhances the reliability and security of data transmission through a functional safety fault monitoring mechanism.
Smart Images

Figure CN120956558A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and more specifically to a data processing method, apparatus, and electronic device based on an Ethernet ring network. Background Technology
[0002] Currently, vehicle functional safety data transmission mainly relies on traditional bus technologies such as CAN / CAN FD and FlexRay. Although CAN / CAN FD has a maximum transmission rate of 1Mbps / 5Mbps, it cannot meet the data interaction requirements of GB per second in L3+ autonomous driving scenarios. Although FlexRay can achieve latency control of 20-100us, it is difficult to adapt to application scenarios with demanding real-time requirements, such as drive-by-wire chassis.
[0003] Furthermore, traditional Ethernet applications lack functional safety-level fault monitoring mechanisms. When random hardware component failures occur in chips and peripheral circuits, or when errors occur in software logic judgments or code execution, the lack of effective monitoring and diagnostic measures means that such failures can directly affect Ethernet communication and lead to related functional abnormalities. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a data processing method, apparatus and electronic device based on an Ethernet ring network to solve the problems that traditional vehicle bus technology cannot meet the high bandwidth and strong real-time requirements of L3+ autonomous driving, while traditional Ethernet applications lack functional safety fault monitoring mechanisms, making it difficult to ensure the reliability and security of data transmission.
[0005] In a first aspect, embodiments of the present invention provide a data processing method based on an Ethernet ring network, the method being applied to a main controller, the method comprising:
[0006] Receive raw input data sent by the electronic control unit located outside the Ethernet ring network;
[0007] The original input data is transmitted based on the first transmission path, and a security protection operation is performed on the original input data during the transmission process to transmit the obtained first input data to the first area controller.
[0008] The original input data is transmitted based on the second transmission path, and the original input data is protected during the transmission process. The obtained second input data is transmitted to the second area controller. After receiving the second input data, the second area controller transmits the second input data to the first area controller.
[0009] The system receives the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
[0010] Furthermore, after receiving the data processing result fed back by the first area controller, the method further includes:
[0011] Obtain the fault codes carried in the data processing results;
[0012] If the fault code indicates that there is a faulty transmission path, then the redundancy switching strategy corresponding to the faulty transmission path is obtained, and the corresponding path switching operation is performed according to the redundancy switching strategy.
[0013] Furthermore, the step of performing the corresponding path switching operation according to the redundancy switching strategy includes:
[0014] If the faulty transmission path is either the first transmission path or the second transmission path, then switch to another transmission path other than the faulty transmission path to send data to the first area controller.
[0015] If the faulty transmission path is the first transmission path and the second transmission path, a reset operation is performed, and after the reset, data is sent to the first area controller based on the transmission path in the first transmission path and the second transmission path where there is no fault.
[0016] Furthermore, the method also includes:
[0017] If the first transmission path and the second transmission path still fail after the reset, the first area controller is notified to stop sending output data and a system fault message is sent.
[0018] Secondly, embodiments of the present invention provide a data processing method based on an Ethernet ring network, the method being applied to a first area controller, the method comprising:
[0019] The system receives first input data sent by the main controller based on the first transmission path, and receives second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path.
[0020] The end-to-end protection mechanisms of the first transmission path and the second transmission path are verified using the first input data and the second input data respectively, and the verification results are obtained.
[0021] Based on the verification result, perform corresponding security processing operations on the original input data.
[0022] Furthermore, the step of verifying the end-to-end protection mechanism of the first transmission path and the second transmission path using the first input data and the second input data respectively, and obtaining the verification result, includes:
[0023] The first input data is used to verify the end-to-end protection mechanism of the first transmission path;
[0024] If the end-to-end protection mechanism of the first transmission path passes the verification, then the verification result is "verification passed"; or,
[0025] If the end-to-end protection mechanism verification of the first transmission path fails, the end-to-end protection mechanism of the second transmission path is verified using the second input data. If the end-to-end protection mechanism verification of the second transmission path passes, the verification result is "verification passed"; or...
[0026] If the end-to-end protection mechanism verification of the first transmission path fails, and the end-to-end protection mechanism verification of the second transmission path fails, then the verification result is that the verification fails.
[0027] Furthermore, the step of performing corresponding security processing operations on the original input data based on the verification result includes:
[0028] If the verification result is successful, the original input data and application instructions are obtained, the original input data is converted into output data based on the application instructions, and the output data is sent to the main controller.
[0029] If the verification result is that the verification failed, a fault code is obtained and the fault code is sent to the main controller.
[0030] Thirdly, embodiments of the present invention provide a data processing apparatus based on an Ethernet ring network, the apparatus comprising:
[0031] The first receiving module is used to receive raw input data sent by the electronic control unit located outside the Ethernet ring network;
[0032] The first processing module is used to transmit the original input data based on the first transmission path, and to perform security protection operations on the original input data during the transmission process, and to transmit the obtained first input data to the first area controller.
[0033] The second processing module is used to transmit the original input data based on the second transmission path, and to perform security protection operations on the original input data during the transmission process, and to transmit the obtained second input data to the second area controller, wherein the second area controller, after receiving the second input data, will transmit the second input data transparently to the first area controller.
[0034] The acquisition module is used to receive the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
[0035] Fourthly, embodiments of the present invention provide a data processing apparatus based on an Ethernet ring network, the apparatus comprising:
[0036] The second receiving module is used to receive first input data sent by the main controller based on the first transmission path, and to receive second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path;
[0037] The verification module is used to verify the end-to-end protection mechanism of the first transmission path and the second transmission path using the first input data and the second input data respectively, and obtain the verification result.
[0038] The execution module is used to perform corresponding security processing operations on the original input data based on the verification result.
[0039] Thirdly, embodiments of the present invention provide an electronic device, including: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the method described in the first aspect or any corresponding embodiment thereof.
[0040] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions that cause a computer to perform the method described in the first aspect or any of its corresponding embodiments.
[0041] This application firstly utilizes an Ethernet ring network to receive raw input data from the electronic control unit, leveraging Ethernet's high bandwidth to achieve rapid transmission of massive amounts of data. This solves the problem of low bandwidth in traditional vehicle bus technology, which cannot meet the high bandwidth requirements of L3+ autonomous driving, thus ensuring real-time data transmission. Secondly, based on a dual-transmission path design, safety protection operations are implemented throughout the data transmission process. Data is transmitted separately to different area controllers, and the second area controller transmits data transparently to the first area controller, solving the problem of traditional Ethernet lacking a functional safety fault monitoring mechanism. Then, the first area controller performs cross-verification on the two data streams to determine the processing result, enhancing the reliability and security of data transmission. This provides strong support for L3+ autonomous driving. Attached Figure Description
[0042] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0043] Figure 1 This is a flowchart illustrating a data processing method based on an Ethernet ring network according to some embodiments of the present invention;
[0044] Figure 2 This is a schematic diagram of an Ethernet architecture according to some embodiments of the present invention;
[0045] Figure 3 This is a flowchart illustrating another data processing method based on an Ethernet ring network according to some embodiments of the present invention;
[0046] Figure 4 This is a schematic diagram of the internal structure of a controller according to some embodiments of the present invention;
[0047] Figure 5 This is a structural block diagram of a data processing device based on an Ethernet ring network according to an embodiment of the present invention;
[0048] Figure 6 This is a structural block diagram of a data processing device based on an Ethernet ring network according to an embodiment of the present invention;
[0049] Figure 7 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0051] According to embodiments of the present invention, a data processing method, apparatus, and electronic device based on an Ethernet ring network are provided. It should be noted that the steps shown in the flowcharts in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0052] This embodiment provides a data processing method based on an Ethernet ring network, which is applied to the main controller. Figure 1 This is a flowchart of a data processing method based on an Ethernet ring network according to an embodiment of the present invention, such as... Figure 1 As shown, the process includes the following steps:
[0053] Step S101: Receive raw input data sent by the electronic control unit located outside the Ethernet ring network.
[0054] In the embodiments of this application, such as Figure 2 As shown, in the vehicle Ethernet redundant backbone ring network architecture, the Body Controller (BC) serves as the central brain of the vehicle's electronic and electrical architecture, undertaking the responsibilities of logical judgment, signal routing, and basic function management, such as controlling the vehicle's sleep / wake-up and diagnostic flashing. It also supports its own function upgrades and diagnostics, and is the core hub for ring network data interaction. The Left Zone Controller (ZCL) and Right Zone Controller (ZCR) receive instructions from the BC through the ring network, and are responsible for executing the actions of actuators such as seats, doors, windows, and lights, sensing external sensor signals, and distributing power to downstream loads.
[0055] The three components are tightly interconnected via an Ethernet ring network conforming to the IEEE 802.1CB standard. The main controller, acting as the data entry point, integrates external signals and routes them to the second and first area controllers. The second area controller can act as a data relay node, transmitting data to the first area controller through redundant paths, reducing wiring complexity. After executing actions, the second and first area controllers feed back the results to the main controller, forming a data closed loop. This architecture not only achieves hierarchical collaborative control of the entire vehicle's functions but also, through its flexible ring network design, is compatible with existing CAN / LIN networks, improving data transmission efficiency and functional safety levels.
[0056] In this embodiment, the main controller acts as the access interface of the Ethernet ring network, receiving raw input data (DATA1) from the electronic control unit outside the ring network through a preset physical interface (such as an RJ45 Ethernet port). This data type includes, but is not limited to, vehicle bus signals such as CAN and LIN. The microcontroller inside the main controller performs protocol conversion and format encapsulation on the input data to adapt it to the Ethernet transmission standard, and generates corresponding identification information (such as signal tags and priority tags) according to the data source and functional attributes, providing a foundation for subsequent dual-path transmission and application command matching.
[0057] Step S102: Transmit the original input data based on the first transmission path, and perform security protection operations on the transmitted data during the transmission process, and transmit the obtained first input data to the first area controller;
[0058] In the embodiments of this application, the role of the first area controller can be flexibly defined as either a left area controller or a right area controller according to the actual application scenario, without any specific limitation. For ease of explanation, the following embodiments will be described with the first area controller as the right area controller, in which case the second area controller corresponds to the left area controller.
[0059] In this embodiment, when transmitting the original input data based on the first transmission path (Path1), a checksum generated by the Cyclic Redundancy Check (CRC) algorithm is first embedded in the data to form a dual check with the Ethernet native Frame Check Sequence (FCS). Microcontroller hardware acceleration technology is used to reduce computational overhead and ensure data integrity. Simultaneously, gPTP time synchronization and gated list traffic scheduling in Time-Sensitive Networking (TSN) technology are used to achieve microsecond-level latency control to ensure real-time performance. Furthermore, a sequence number and timestamp are added to the data, and the high-precision synchronization capability of TSN enables end-to-end traceability. After completing the above security verification process, the main controller transmits the first input data to the first area controller via a direct Ethernet interface.
[0060] Specifically, when transmitting raw input data based on the first transmission path (Path1), the microcontroller of the main controller calls the hardware CRC calculation unit to generate a 32-bit check code for the raw data and embed it into a specific field of the data frame. At the same time, it automatically attaches an FCS check sequence to form a dual check mechanism.
[0061] Meanwhile, TSN technology ensures microsecond-level real-time performance. The Ethernet switches of the main controller and the first area controller establish sub-microsecond clock synchronization based on the gPTP protocol, with clock deviation controlled within ±200ns. A gated list scheduling mechanism allocates a dedicated transmission window to Path1, opening a 200μs high-priority time slot every 10ms period, granting absolute transmission rights to critical safety data (such as braking signals). This scheduling strategy stabilizes the end-to-end latency of Path1 within 40μs, with jitter not exceeding ±5μs, meeting the deterministic transmission requirements of real-time sensitive applications such as drive-by-wire chassis.
[0062] During the data encapsulation phase, the main controller assigns a unique, incrementing sequence number (32-bit unsigned integer) to each data frame and adds a 64-bit timestamp based on the gPTP synchronization clock. This metadata, together with the data content, constitutes a traceable data packet. When the first area controller receives the data, it performs fault diagnosis by comparing the sequence number continuity and the timestamp offset (ΔT): if ΔT exceeds 50μs or the sequence number jumps by ≥2, the path anomaly handling process is triggered.
[0063] Step S103: Transmit the original input data based on the second transmission path, and perform security protection operations on the transmitted data during the transmission process. Transmit the obtained second input data to the second area controller. After receiving the second input data, the second area controller transmits the second input data to the first area controller.
[0064] In this embodiment of the application, when transmitting the original input data based on the second transmission path (Path2), the microcontroller of the main controller calls the hardware CRC calculation unit to generate a 32-bit check code for the original data and embed it into the data frame, while automatically attaching FCS to form double verification.
[0065] When data arrives at the second area controller, its built-in Ethernet switch executes a no-parse pass-through mechanism. The microcontroller of the second area controller only performs physical layer forwarding verification on the data frames, maintaining the original data format unchanged through hardware pass-through mode to avoid delays and errors introduced by protocol conversion. During pass-through, the TSN switch of the second area controller synchronously updates the timestamp offset, calibrates the transmission delay (typically 15μs) based on the gPTP protocol, and ensures microsecond-level deterministic transmission of data in the link between the second area controller and the first area controller through gated list scheduling.
[0066] In the end-to-end transmission of Path2, the sequence number and timestamp form a traceable chain. The main controller assigns an incrementing sequence number to each frame of data, and the second area controller appends its own MAC address as a path identifier during transparent transmission, forming a transmission log chain of main controller → second area controller → first area controller. After receiving the data, the first area controller verifies it through a triple check mechanism: comparing the FCS with the upper-layer CRC to ensure integrity, verifying the continuity of the sequence number (allowing jumps ≤ 1), and determining real-time performance through the timestamp offset (ΔT ≤ 50μs). If an anomaly is detected in Path2 (such as a CRC error or timeout), the first area controller automatically switches to the Path1 priority processing logic to ensure functional safety redundancy.
[0067] Step S104: Receive the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
[0068] In this embodiment, after the first area controller performs E2E verification on the received Path1 and Path2 data, it feeds back the data processing results (such as whether the verification passed, fault codes, etc.) to the main controller via the CAN bus. Upon receiving the feedback, the main controller parses the fault codes in the processing results (e.g., 0x1234 according to the SAE J1939-73 standard indicates dual-path failure), locates the faulty transmission path, and executes corresponding operations according to a preset strategy: if the dual-path verification is normal, the main controller maintains the current data transmission configuration; if a single path is abnormal, the main controller initiates a redundancy switching strategy; if both paths fail, the main controller notifies the human-machine interface (HMI) via the Ethernet link to issue a warning to the driver and records the fault information to the on-board diagnostic system.
[0069] In this embodiment of the application, after receiving the data processing result fed back by the first area controller, the method further includes the following steps A1-A2:
[0070] Step A1: Obtain the fault codes carried in the data processing results.
[0071] Specifically, the main controller receives data processing results from the first area controller via the CAN bus. These results include fault codes encoded according to the SAE J1939-73 standard. The main controller's microcontroller parses the received data processing results, extracts fault codes from specific fields, and identifies the corresponding fault type if an anomaly is found. For example, "0x1234" indicates a dual-path end-to-end detection failure.
[0072] Step A2: If the fault code indicates that there is a faulty transmission path, obtain the redundancy switching strategy corresponding to the faulty transmission path and perform the corresponding path switching operation according to the redundancy switching strategy.
[0073] Specifically, the redundancy switching strategy is a pre-defined set of path management rules designed to ensure the reliability and continuity of data transmission in the vehicle-mounted Ethernet ring network.
[0074] Among them, the corresponding path switching operations are performed according to the redundancy switching strategy, including:
[0075] ① If the faulty transmission path is either the first transmission path or the second transmission path, then switch to the other transmission path (excluding the faulty transmission path) to send data to the first area controller.
[0076] Understandably, when the faulty transmission path is either the first or second transmission path, the fault handling module within the main controller quickly identifies the faulty path and sends a path switching command to the Ethernet switch via the internal communication bus. Upon receiving the command, the switch immediately adjusts its data forwarding rules, redirecting the original input data that was originally transmitted through the faulty path to another normal transmission path. Simultaneously, the main controller updates its data routing table to ensure that subsequent data continues to be stably transmitted to the first area controller via the normal path, thereby guaranteeing the continuity and reliability of data transmission and preventing data interruption due to a single path failure.
[0077] ② If the faulty transmission path is the first transmission path or the second transmission path, then a reset operation is performed, and after the reset, data is sent to the first area controller based on the transmission path in the first and second transmission paths where there is no fault.
[0078] Understandably, if both the first and second transmission paths fail simultaneously, the main controller first sends a reset signal to the relevant Ethernet switch (e.g., Switch1) via a hardwired interface to force a hardware restart and attempt to restore its normal operating state. After the reset operation, the main controller initiates a path status detection program, quickly determining the recovery status of the first and second transmission paths by sending test data packets and monitoring responses. Once a path is detected as restored to normal, the main controller immediately switches the data transmission task to that fault-free path and reconfigures the Ethernet switch's forwarding policy, enabling the original input data to continue transmitting to the first area controller via the restored path, thus achieving rapid repair and reconstruction of the data transmission link.
[0079] In this embodiment of the application, the method further includes: if the first transmission path and the second transmission path still fail after the reset, the first area controller is notified to stop sending output data and a system fault prompt message is sent.
[0080] Specifically, if, after a reset operation, the main controller confirms that faults still exist in both the first transmission path (Path1) and the second transmission path (Path2) by sending test data packets and monitoring responses, the main controller immediately sends a stop output command to the first area controller via the CAN bus. Upon receiving the command, the first area controller, in accordance with functional safety design requirements, immediately stops sending DATA2 data to prevent erroneous data from causing system risks. Simultaneously, the main controller transmits system fault information to the HMI via an Ethernet link. This information includes a fault code (such as 0x1234 corresponding to dual-path failure) and a fault description to warn the driver of the current abnormality in the vehicle's network transmission system. The fault information is also written into the vehicle diagnostic system to provide data support for subsequent maintenance, forming a complete fault-safe closed loop.
[0081] This application firstly utilizes an Ethernet ring network to receive raw input data from the electronic control unit, leveraging Ethernet's high bandwidth to achieve rapid transmission of massive amounts of data. This solves the problem of low bandwidth in traditional vehicle bus technology, which cannot meet the high bandwidth requirements of L3+ autonomous driving, thus ensuring real-time data transmission. Secondly, based on a dual-transmission path design, safety protection operations are implemented throughout the data transmission process. Data is transmitted separately to different area controllers, and the second area controller transmits data transparently to the first area controller, solving the problem of traditional Ethernet lacking a functional safety fault monitoring mechanism. Then, the first area controller performs cross-verification on the two data streams to determine the processing result, enhancing the reliability and security of data transmission. This provides strong support for L3+ autonomous driving.
[0082] Figure 3 This is a flowchart of a data processing method based on an Ethernet ring network according to an embodiment of the present invention, such as... Figure 3 As shown, the role of the method applied to the first area controller can be flexibly defined as either the left area controller or the right area controller depending on the actual application scenario; no specific limitation is made. For ease of explanation, the following embodiments will be described with the first area controller as the right area controller, in which case the second area controller corresponds to the left area controller. The process includes the following steps:
[0083] Step S201: Receive first input data sent by the main controller based on the first transmission path, and receive second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path.
[0084] In this embodiment, the first area controller receives two data streams in parallel via an Ethernet interface. On one hand, it receives first input data directly transmitted from the main controller via the first transmission path (Path1). On the other hand, it receives second input data transparently transmitted by the second area controller. This second input data is the original input data first sent by the main controller to the second area controller via the second transmission path (Path2), and then forwarded by the second area controller to the first area controller without parsing. The first area controller uses MAC address filtering and VLAN tag identification to buffer the two data streams into different receiving queues, ensuring the traceability of the data source.
[0085] Step S202: Use the first input data and the second input data to verify the end-to-end protection mechanism of the first transmission path and the second transmission path respectively, and obtain the verification result.
[0086] In this embodiment, the microcontroller of the first area controller performs triple verification on the two data streams synchronously. First, it compares the Ethernet native FCS with the upper-layer protocol CRC to verify data integrity; second, it verifies the sequence number continuity to determine if there are any dropped frames; finally, it compares the timestamp with the local gPTP clock to calculate whether the transmission delay exceeds a threshold (e.g., 50μs). For the first input data transmitted via Path1, the direct link between the main controller and the first area controller is the primary focus of verification; for the second input data transmitted via Path2, the continuity of the timestamp during the transparent transmission process to the second area controller is additionally verified, forming an E2E detection covering the entire link.
[0087] Specifically, the end-to-end protection mechanisms of the first and second transmission paths are verified using the first and second input data, respectively, to obtain the verification results, including:
[0088] ①If the end-to-end protection mechanism of the first transmission path passes the verification, the verification result is "verification passed".
[0089] Understandably, when the first area controller receives the first input data sent by the main controller via the first transmission path (Path1), it immediately initiates the E2E verification process. If both the Ethernet native FCS and the upper-layer protocol CRC double verification are correct, the sequence number is continuous without jumps, and the timestamp shows a transmission delay within the threshold (e.g., 50μs), then Path1 verification is considered successful. At this time, the first area controller directly uses the Path1 data to generate output (DATA2) and feeds back the "Path1 normal" status to the main controller via the CAN bus. Simultaneously, it uses the data from the second transmission path (Path2) as a hot backup buffer, forming a "main path priority + backup path hot standby" security mechanism.
[0090] ② If the end-to-end protection mechanism of the first transmission path fails the verification, the end-to-end protection mechanism of the second transmission path is verified using the second input data. If the end-to-end protection mechanism of the second transmission path passes the verification, the verification result is "verification passed".
[0091] Understandably, when Path1 verification encounters a CRC error, sequence number jump ≥2, or delay exceeds the limit, the first area controller immediately switches to verifying Path2 data. For the second input data passed through by the second area controller, the first area controller first verifies its source legitimacy (via MAC address and VLAN tag), then repeats CRC / FCS comparison, sequence number verification, and timestamp analysis. If Path2 verification passes, the first area controller automatically switches to Path2 data generation to DATA2 and reports "Path1 fault, switched to Path2" to the main controller. Simultaneously, it triggers the fault diagnosis process for Path1 (e.g., sending test frames to check link status) to ensure the system can still operate safely under single-path failure.
[0092] ③ If the end-to-end protection mechanism verification of the first transmission path fails, and the end-to-end protection mechanism verification of the second transmission path fails, then the verification result is that the verification fails.
[0093] Understandably, when the first area controller detects verification anomalies in both Path1 and Path2 data (such as dual-path CRC errors or simultaneous delay exceeding limits), it immediately executes a safety degradation strategy. The first area controller stops sending DATA2 data, sends a fault code (such as 0x1234) to the main controller via the CAN bus, and writes the fault details (including timestamp, error type, checksum, etc.) to non-volatile memory. Simultaneously, the main controller notifies the human-machine interface via Ethernet to display a "dual-path failure" warning to the driver, and the system enters a fail-safe state to prevent erroneous data from affecting critical functions.
[0094] Step S203: Perform corresponding security processing operations on the original input data based on the verification results.
[0095] In this embodiment, the first area controller performs a tiered response based on the verification results. If both data paths pass verification, Path1 data is used to generate output (DATA2), while Path2 is recorded as a hot backup. If only Path2 passes verification, the system switches to Path2 data and triggers a fault report for Path1. If both paths fail, the first area controller stops sending DATA2, transmits a fault code (e.g., 0x1234) to the main controller via the CAN bus, and stores a detailed fault log (including timestamps, CRC error values, serial number transitions, etc.) internally to provide a basis for subsequent diagnosis and ensure that the system still meets ASILD level safety requirements under fault conditions.
[0096] In this embodiment of the application, the corresponding security processing operation is performed on the original input data based on the verification result, including: if the verification result is that the verification passes, the original input data and application instructions are obtained, the original input data is converted into output data based on the application instructions, and the output data is sent to the main controller; if the verification result is that the verification fails, a fault code is obtained and the fault code is sent to the main controller.
[0097] Understandably, once the first area controller confirms that either the first transmission path (Path1) or the second transmission path (Path2) has passed verification, it extracts the original input data (such as steering angle, vehicle speed, etc.) from the verified data frame. Simultaneously, it matches the corresponding instruction (such as "convert steering wheel angle into motor control signal") from its internally stored application instruction table. The microcontroller of the first area controller performs format conversion, unit conversion, and logical operations on the original data based on the application instruction, generating DATA2 data that conforms to the output protocol (such as control instructions in CAN frame format). Subsequently, the first area controller sends DATA2 to the main controller via the Ethernet interface, adding a path status identifier (such as "Path1 normal") to the frame header to ensure that the main controller can accurately identify the data source and quality status.
[0098] When the first area controller determines that both Path1 and Path2 have failed verification, it immediately terminates the data processing flow and stops sending output data (DATA2) to prevent erroneous data from affecting system security. The fault management module of the first area controller reads detailed fault information (such as CRC error value, number of sequence number transitions, delay exceeding limit, etc.) from the internal error register and generates a fault code according to the SAE J1939-73 standard (e.g., 0x1234 indicates dual-path failure). This code is encapsulated into a diagnostic frame via the CAN bus and sent to the main controller. At the same time, the first area controller writes the system status at the time of the fault (such as timestamp, comparison of the two data verification values) into non-volatile memory, providing a backtracking basis for subsequent fault diagnosis and ensuring that the system can still achieve safety status reporting and data traceability under abnormal conditions.
[0099] In this embodiment, the microcontrollers within the main controller, the first area controller, and the second area controller establish a heartbeat monitoring mechanism with the corresponding Ethernet switch via a communication bus. For example... Figure 4As shown, an external PowerSupply powers the EthernetSwitch. The microcontroller monitors the voltage and enables the switch via a communication bus (such as SPI / I2C), while simultaneously performing an active reset of the switch using a hard-wired Reset interface. Taking BC as an example, Ethernet Switch1 periodically sends a "heartbeat" signal containing a timestamp and status code to microcontroller1. If microcontroller1 detects a signal timeout or abnormal content (such as a transmission time exceeding the ±500μs window), it determines that Switch1 is malfunctioning, triggers a reset, and suspends data transmission at the BC end. At this time, ZCR detects the BC malfunction through the E2E mechanism, reports the fault, and stops sending Data2 data. The monitoring logic of microcontrollers 2 and 3 of ZCL and ZCR for their respective switches is consistent. However, the reset of Switch2 in ZCL only interrupts Path2 and does not affect the transmission of Path1.
[0100] In addition, to meet the higher Automotive Safety Integrity Level (ASIL) requirements, microcontroller 1 / microcontroller 2 / microcontroller 3 monitor key internal hardware modules in real time: the clock module detects crystal drift (allowing ±50ppm) via a PLL counter; the memory module performs Error Detection and Correction (EDAC) verification and static random-access memory (SRAM) bit-to-bit flip-flop testing; the power module monitors the VDD voltage (3.3V±5%); the kernel uses a watchdog timer (200ms overflow time) to detect program crashes; and the program flow traces the instruction sequence via the bus. If a fault is detected, the microcontroller first writes safety-related data (such as path status and fault codes) to non-volatile memory (NVM), triggers a system reset after a 5ms delay, and blocks Ethernet output via hardware logic during the reset to prevent abnormal data transmission.
[0101] Ethernet Switch1 / 2 / 3 identifies functional safety-related faults through internal fault diagnosis modules (such as memory verification, power monitoring, and clock / temperature / register monitoring). Upon detecting an anomaly, it notifies the microcontroller via the communication bus, triggering a reset and resetting the PowerSupply (rebooting 50ms after power failure). To prevent the diagnostic mechanism from malfunctioning and becoming a latent fault, the microcontroller and Switch perform a comprehensive self-test upon power-up (e.g., the microcontroller sends simulated error data verification responses to the memory verification module, and the Switch self-tests the diagnostic circuitry). Upon power-down, the microcontroller records the status of the diagnostic modules to ensure the diagnostic mechanism is effective upon the next power-up. This mechanism, through hardware and software collaboration, forms a closed loop of "fault detection-reset-self-test," ensuring the functional safety level of the Ethernet ring network.
[0102] In addition, the microcontroller samples the power supply voltage provided by PowerSupply to the EthernetSwitch in real time via the ADC channel (normal range assumed to be 3.3V±10%). When the voltage is detected to be lower than 2.97V or higher than 3.63V, it immediately determines that a power supply abnormality may cause abnormal data transmission by the Switch. At this time, the microcontroller triggers a Switch reset through the hard-wired Reset interface, and simultaneously controls PowerSupply to shut down and then restart the power supply for 50ms. This "power-off-reset-restart" process attempts to restore the Switch to normal working state, avoiding communication failures caused by power fluctuations.
[0103] To differentiate between temporary and permanent faults, the system manages the number of Ethernet switch resets. If the same switch is reset a total of 3 times during operation, the microcontroller determines that there is an unrecoverable hardware fault, directly disables the Ethernet communication function (pulls the TX_EN pin low), reports a fault code to the vehicle diagnostic system via the CAN bus, and displays a warning on the Human-Machine Interface (HMI). Similarly, if the microcontroller's own system resets a total of 5 times within a driving cycle, it will prevent power-on again, and the fault information will be stored in the NVM. By using a reset threshold, the system prevents the fault from spreading and ensures that the safety degradation meets ASIL level requirements.
[0104] This embodiment also provides a data processing device based on an Ethernet ring network, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0105] This embodiment provides a data processing device based on an Ethernet ring network, such as... Figure 5 As shown, it includes:
[0106] The first receiving module 501 is used to receive raw input data sent by the electronic control unit located outside the Ethernet ring network;
[0107] The first processing module 502 is used to transmit the original input data based on the first transmission path, and to perform security protection operations on the transmitted data during the transmission process, and to transmit the obtained first input data to the first area controller.
[0108] The second processing module 503 is used to transmit the original input data based on the second transmission path, and to perform security protection operations on the transmitted data during the transmission process, and to transmit the obtained second input data to the second area controller. The second area controller, after receiving the second input data, transmits the second input data to the first area controller.
[0109] The acquisition module 504 is used to receive the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
[0110] In this embodiment of the application, the device further includes: a switching module, used to obtain fault codes carried in the data processing results; if the fault code indicates that there is a faulty transmission path, then obtain the redundancy switching strategy corresponding to the faulty transmission path, and perform the corresponding path switching operation according to the redundancy switching strategy.
[0111] In this embodiment of the application, the switching module is used to switch to another transmission path other than the faulty transmission path to send data to the first area controller if the faulty transmission path is either the first transmission path or the second transmission path.
[0112] The switching module is used to perform a reset operation if the faulty transmission path is the first transmission path or the second transmission path, and after the reset, to send data to the first area controller based on the transmission path in the first and second transmission paths where there is no fault.
[0113] In this embodiment of the application, the device further includes: a prompting module, used to notify the first area controller to stop sending output data and send a system fault prompt message if the first transmission path and the second transmission path still fail after a reset.
[0114] This embodiment also provides a data processing device based on an Ethernet ring network, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0115] This embodiment provides a data processing device based on an Ethernet ring network, such as... Figure 6 As shown, it includes:
[0116] The second receiving module 601 is used to receive first input data sent by the main controller based on the first transmission path, and to receive second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path.
[0117] The verification module 602 is used to verify the end-to-end protection mechanism of the first transmission path and the second transmission path using the first input data and the second input data respectively, and obtain the verification result.
[0118] The execution module 603 is used to perform corresponding security processing operations on the original input data based on the verification results.
[0119] In this embodiment of the application, the verification module 602 is used to verify the end-to-end protection mechanism of the first transmission path using the first input data; if the end-to-end protection mechanism of the first transmission path passes the verification, the verification result is verification passed; or, if the end-to-end protection mechanism of the first transmission path fails the verification, the end-to-end protection mechanism of the second transmission path is verified using the second input data; if the end-to-end protection mechanism of the second transmission path passes the verification, the verification result is verification passed; or, if the end-to-end protection mechanism of the first transmission path fails the verification and the end-to-end protection mechanism of the second transmission path fails the verification, the verification result is verification failed.
[0120] In this embodiment of the application, the execution module 603 is used to obtain the original input data and application instructions if the verification result is that the verification is passed, convert the original input data into output data based on the application instructions, and send the output data to the main controller; if the verification result is that the verification is failed, obtain the fault code and send the fault code to the main controller.
[0121] Please see Figure 7 , Figure 7 This is a schematic diagram of the structure of an electronic device provided in an optional embodiment of the present invention, such as... Figure 7As shown, the electronic device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise as required. The processors can process instructions executed within the electronic device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system).
[0122] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0123] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.
[0124] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device as displayed on a mini-program landing page. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0125] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0126] The electronic device also includes a communication interface 30 for communicating with other devices or communication networks.
[0127] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0128] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A data processing method based on an Ethernet ring network, characterized in that, The method is applied to the main controller, and the method includes: Receive raw input data sent by the electronic control unit located outside the Ethernet ring network; The original input data is transmitted based on the first transmission path, and a security protection operation is performed on the original input data during the transmission process to transmit the obtained first input data to the first area controller. The original input data is transmitted based on the second transmission path, and the original input data is protected during the transmission process. The obtained second input data is transmitted to the second area controller. After receiving the second input data, the second area controller transmits the second input data to the first area controller. The system receives the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
2. The method according to claim 1, characterized in that, After receiving the data processing result fed back by the first area controller, the method further includes: Obtain the fault codes carried in the data processing results; If the fault code indicates that there is a faulty transmission path, then the redundancy switching strategy corresponding to the faulty transmission path is obtained, and the corresponding path switching operation is performed according to the redundancy switching strategy.
3. The method according to claim 2, characterized in that, The step of performing the corresponding path switching operation according to the redundancy switching strategy includes: If the faulty transmission path is either the first transmission path or the second transmission path, then switch to another transmission path other than the faulty transmission path to send data to the first area controller. If the faulty transmission path is the first transmission path and the second transmission path, a reset operation is performed, and after the reset, data is sent to the first area controller based on the transmission path in the first transmission path and the second transmission path where there is no fault.
4. The method according to claim 3, characterized in that, The method further includes: If the first transmission path and the second transmission path still fail after the reset, the first area controller is notified to stop sending output data and a system fault message is sent.
5. A data processing method based on an Ethernet ring network, characterized in that, The method is applied to a first area controller, and the method includes: The system receives first input data sent by the main controller based on the first transmission path, and receives second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path. The end-to-end protection mechanisms of the first transmission path and the second transmission path are verified using the first input data and the second input data respectively, and the verification results are obtained. Based on the verification result, perform corresponding security processing operations on the original input data.
6. The method according to claim 5, characterized in that, The step of verifying the end-to-end protection mechanism of the first transmission path and the second transmission path using the first input data and the second input data respectively, and obtaining the verification result, includes: The first input data is used to verify the end-to-end protection mechanism of the first transmission path; If the end-to-end protection mechanism of the first transmission path passes the verification, then the verification result is "verification passed"; or, If the end-to-end protection mechanism verification of the first transmission path fails, the end-to-end protection mechanism of the second transmission path is verified using the second input data. If the end-to-end protection mechanism verification of the second transmission path passes, the verification result is "verification passed"; or... If the end-to-end protection mechanism verification of the first transmission path fails, and the end-to-end protection mechanism verification of the second transmission path fails, then the verification result is that the verification fails.
7. The method according to claim 5, characterized in that, The step of performing corresponding security processing operations on the original input data based on the verification result includes: If the verification result is successful, the original input data and application instructions are obtained, the original input data is converted into output data based on the application instructions, and the output data is sent to the main controller. If the verification result is that the verification failed, a fault code is obtained and the fault code is sent to the main controller.
8. A data processing device based on an Ethernet ring network, characterized in that, The device includes: The first receiving module is used to receive raw input data sent by the electronic control unit located outside the Ethernet ring network; The first processing module is used to transmit the original input data based on the first transmission path, and to perform security protection operations on the original input data during the transmission process, and to transmit the obtained first input data to the first area controller. The second processing module is used to transmit the original input data based on the second transmission path, and to perform security protection operations on the original input data during the transmission process, and to transmit the obtained second input data to the second area controller, wherein the second area controller, after receiving the second input data, will transmit the second input data transparently to the first area controller. The acquisition module is used to receive the data processing result fed back by the first area controller, wherein the data processing result is determined by the first area controller after verifying the first transmitted data and the second transmitted data.
9. A data processing device based on an Ethernet ring network, characterized in that, The device includes: The second receiving module is used to receive first input data sent by the main controller based on the first transmission path, and to receive second input data transmitted by the second area controller, wherein the second input data is the original input data sent by the main controller to the second area controller based on the second transmission path; The verification module is used to verify the end-to-end protection mechanism of the first transmission path and the second transmission path using the first input data and the second input data respectively, and obtain the verification result. The execution module is used to perform corresponding security processing operations on the original input data based on the verification result.
10. An electronic device, characterized in that, include: A memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, the processor executing the computer instructions to perform the method of any one of claims 1 to 7.